CVE-1999-0693: Buffer Overflow
Buffer overflow in TTSESSION environment variable in ToolTalk shared library allows local users to gain root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
ToolTalk shared libraryfrom your environment.Uninstall or remove the ToolTalk shared library (or the ToolTalk package) from systems where it is not required to eliminate the vulnerable component.
- Configuration
Ensure the TT_SESSION environment variable is not honored by privileged processes: clear or sanitize TT_SESSION from the environment before loading the ToolTalk shared library and ensure setuid/setgid binaries do not inherit TT_SESSION.
ToolTalk shared library TT_SESSION environment variable handling = sanitize/clear - Compensating control
Restrict local access and limit which local accounts can execute programs that load the ToolTalk shared library (e.g., restrict logins, use host-based access controls or sudoers rules) until a proper fix is available.
- Operational
If compromise is suspected (local users may have obtained root), perform incident response: investigate for unauthorized changes/backdoors, reinstall from trusted media or restore from known-good backups, and rotate root and other administrative credentials.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0693?
CVE-1999-0693 is classified as a high-severity vulnerability due to its potential to grant local users root privileges.
How do I fix CVE-1999-0693?
To fix CVE-1999-0693, users should update their ToolTalk shared library to a version that addresses this buffer overflow vulnerability.
Who is affected by CVE-1999-0693?
CVE-1999-0693 affects local users on systems running specific versions of HP-UX, AIX, and UnixWare.
What type of vulnerability is CVE-1999-0693?
CVE-1999-0693 is a buffer overflow vulnerability that can be exploited to elevate privileges.
What systems are vulnerable to CVE-1999-0693?
Vulnerable systems include HP-UX 10 and 11, IBM AIX 4, and Xinuos UnixWare 7.